SOC2C

Is this your company? Buyers are checking Revizto here. Claim revizto.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Revizto logo

Revizto

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Revizto is SOC 2 Type II compliant. Revizto also holds ISO 27001, ISO 27017, and CSA STAR.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Revizto is the leading Integrated Collaboration Platform for the Architecture, Engineering, Construction & Operations (AECO) industry, transforming the way we design and build by driving efficiency, reducing errors, and simplifying complexity. From real-time coordination to automated clash detection and issue tracking, Revizto keeps all stakeholders aligned throughout the entire project lifecycle. Backed by Summit Partners, Revizto is relied on by firms around the world like Jacobs, AECOM, AtkinsRealis, McCarthy, Skanska, Stantec, and others to deliver projects with greater confidence and cont

Compliance & infrastructure

ISO 27001ISO 27017SOC 2 Type IICSA STAR
Hosting
AWS
Data handled
Customer personally identifiable informationEmployee personally identifiable informationCredit card informationPersonal health informationCustomer project data

Subprocessors

6
  • A
    AWS · Main Cloud hosting
    Switzerland, UK, Ireland, USA, Australia, Canada, Brazil, Singapore, Japan, United Arab Emirates
  • A
    AliCloud · Separate Cloud hosting
    China, Kingdom of Saudi Arabia
  • M
    Mailgun · Email delivery
    EU/US
  • A
    Amplitude · Analytics
    EU/US
  • Z
    Zendesk · Customer support
    AU
  • S
    Sentry · Error logging
    EU/US

Compliance leadership

The person who leads Revizto's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Revizto's penetration test vendor isn't listed yet.

Claim this profile to add it.

Recent updates

RVZ-SA-2026-002 - SAML Cross-Account Authentication Bypass in Revizto SSOMay 2026

# Security Advisory — RVZ-SA-2026-002 SAML Cross-Account Authentication Bypass in Revizto SSO (SP-initiated flow) | Field | Value | |---|---| | Revizto Vulnerability Advisory ID | RVZ-SA-2026-002 | | Severity (CVSS 3.1 Base) | 8.2 — High | | CVSS vector | `CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N` | | Affected product / component | Revizto web platform — authentication service, SAML SP-initiated login flow | | Impacted versions | All backend deployments prior to WEB-17260 (github.com/revizto/core PR #3038) | | Mitigated versions | All production regions running post-WEB-17260 backend, deployed by [DD-Mon-2026 — to be filled by Infrastructure] | | Date published | 13-May-2026 | | Last updated | 13-May-2026 | --- ## Summary During an internal security review, the Revizto Application Security team identified and fixed a flaw in the way Revizto handled Single Sign-On (SSO) logins. Under specific conditions, the flaw could have allowed someone with an active Revizto subscription, who also controlled an Identity Provider, to sign in as a different user — even one protected by two-factor authentication — and view or change parts of that user's profile. Revizto is not aware of any exploitation of this vulnerability. The fix is deployed on Revizto's servers across all twelve production regions worldwide. No action is required from customers or end users. Revizto found no evidence…

RVZ-SA-2026-001: Important Information on Axios npm Supply Chain Compromise (plain-crypto-js RAT)Apr 2026

*Related to Revizto Vulnerability Advisory ID: N/A — No advisory issued (Revizto not impacted)* *Severity: CVSS Score 9.8 (Critical) — Impact: Remote Code Execution via supply chain compromise* *Affected Product/Service/Component: npm packages axios@1.14.1, axios@0.30.4, plain-crypto-js@4.2.1 (third-party open-source)* *Impacted Versions: axios 1.14.1, axios 0.30.4* *Mitigated Versions: axios 1.14.0 and earlier; axios >=1.14.2 (once published by maintainers)* Date Published: 01-Apr-2026 Last Updated: 01-Apr-2026 *SUMMARY* On 2026-03-31, a supply chain attack was identified targeting the widely used axios npm package. An attacker (attributed to UNC1069 / GOLDEN CHOLLIMA, a North Korea-linked threat actor) hijacked a maintainer account and published compromised versions 1.14.1 and 0.30.4. These versions include a postinstall script that installs plain-crypto-js@4.2.1, which drops a cross-platform Remote Access Trojan (RAT) targeting Linux, macOS, and Windows. Revizto has conducted a thorough investigation and confirmed that the Revizto Solution, infrastructure, and endpoints are not affected by this vulnerability. *DESCRIPTION* The compromised axios versions execute a malicious postinstall script during npm install that downloads and installs plain-crypto-js@4.2.1. This package deploys a cross-platform RAT capable of providing persistent remote access to the compromised host…

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Documents
    List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Revizto SOC 2 compliant?
Revizto is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Revizto ISO 27001 certified?
According to Revizto's public trust center, Revizto is ISO 27001 certified. On SOC2C this listing is Listed.
Is Revizto ISO 27017 certified?
According to Revizto's public trust center, Revizto is ISO 27017 certified. On SOC2C this listing is Listed.
Is Revizto CSA STAR certified?
According to Revizto's public trust center, Revizto is CSA STAR certified. On SOC2C this listing is Listed.
Is Revizto SOC 2 Type I or Type II?
Revizto is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.